first i would give a short description of our exchange organisation: all servers with ex 2000 /sp1; 1 server which acts as local bridgehead, hosts the connectors and fax-server (gfi) installed. 1 active/active cluster --> they host the mailbox/public folder stores.
On to the problem: message tracking enabled on all 3 servers (with detailed logging). worked great until we made firmware upgrades on the storage controllers a few days ago. we had to reboot all the servers. after the reboot (we did it in the correct way on the cluster) the servers work very well, but i noticed that the message tracking log files became very small on the !!2nd!! cluster node (normally they are between 4 - 12 MB per day depending on the traffic). Now they are between 400 KB and 1,3 MB (the tracking log is ok on the 2 other servers). So I decided to open the files with an editor and i was surprised by the things i have seen (or better 'not' seen): the only entries in the log files are those with event id 1027 and 1028. all other events will not be logged anymore and also outbound mail (internet mail) is logged with a 1027 id, which was logged before with much more entries and a final 1031 ID. so my question is: whats going on? what went wrong? How can I correct this? We need the correct tracking because we do statistics with the log file and other usefull things. alex _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe: mailto:[EMAIL PROTECTED] Exchange List admin: [EMAIL PROTECTED]

